5 ms·
Neither Visa nor Mastercard really implement ISO 8583 a standardized way. Which means they each issue many thousands of pages of documentation covering not only
by ocf 2y ago
Neither Visa nor Mastercard really implement ISO 8583 a standardized way. Which means they each issue many thousands of pages of documentation covering not only which of the standard fields they use and how, but also how they cram their proprietary data into the messages. Most card management/issuance platforms do a decent job of abstracting this away though.
Transition to ISO 20022 would be a positive improvement, but I don't think it will ever meet the required ROI threshold (globally) for that to happen.
- lxgr 2y agoThe large card networks have so many proprietary behaviors and extensions that I really doubt whether any common standard would even make sense at this point. And if you look at how "modern" ISO 8583 is evolving, almost all changes and extensions are already happening in TLV-like subfields (where a new field unexpectedly appearing doesn't make existing parsers explode spectacularly), and the top-level structure is essentially irrelevant. Of course, it's a significant hurdle to newcomers to get familiar with that outer layer, but I don't get the sense that catering to these is a particular focus by either network. ISO 8583 is also a great moat (one of many in the industry, really) for existing processors, which have no buy-in to switch to a new standard and the networks need to at least somewhat keep happy.
- throwway120385 2y agoI thought that chip-in EMV was bad until I saw some of the stuff coming out of Discover cards for contactless EMV. Buying a test card set from somewhere like B2 Systems was very beneficial even just integrating an EMV reader from a hardware device to a payment processor.
- lxgr 2y agoThe problem is that the contactless stuff is all custom per network. Some of the implementations are reasonably close to contact EMV; others might as well be a completely different stack and technology.
- BiteCode_dev 2y agoIn this world and age of AI, having this kind of inside knowledge that is scattered, usually behind paywall and nda, and always to be updated, is a real advantage. Because no LLM will be able to replace you for quite a while.
- happosai 2y agoJob security via obscurity.
- _blk 2y agoYou're right but that's because it's already come to this. Would it have been that hard to say: these are the standardized fields usable only in accordance with the standards and these are the custom fields for your own bs.
- haxrob 2y agoCan attest, having searched through literally thousands of pages of documentation in an attempt to attribute the payment processing switch vendor when analysing the ATM jackpotting malware ‘fast cash for Linux’[1]. The best I could do was determine the currency used for the fraudulent transactions, which may imply the country of the target financial institution. Would be curious if anyone else has further insights. [1] https://haxrob.net/fastcash-for-linux/ https://haxrob.net/fastcash-for-linux/
- dekelpilli 2y agoHaving been involved in several ISO8583 implementations/integrations, it's really quite wild how different each one was in both structure and required content from one another.
- dylanh 2y agothis is the way. Shove everything into field 47. dear god will I never forget all of these terrible details
- sandGorgon 2y agocorrect. which is why people prefer to buy the 8583 implementations. like https://jpos.org/ https://jpos.org/
- cess11 2y agoISO 20022 roll-out is well underway. Unless the US decides to extend it's war on the world to the rest of G20 the plan is to be done a year from now, and if I'm not mistaken the US is a member of the PEPPOL society already. It's the lingua franca of european banks and has been for some time. Back in 2018 when I built a piece of financial software I talked ISO 20022 with a swedish bank in Luxembourg.
- CamouflagedKiwi 2y agoThis is not the case for card networks. I know of no plan for Visa or Mastercard to move to ISO20022 and even if so I am certain it will not be complete within a year from now. In fact, if they announced they were starting a migration like that, I would be dubious if it could be completed within 10 years, there are so many systems out there that would have to change. On many other payment systems, yes, ISO20022 is or is becoming the lingua franca - e.g. FedWire is going to move next year.
- cess11 2y agoThe planning stage is history. https://usa.visa.com/content/dam/VCOM/global/ms/documents/veei-demystifying-iso-20022.pdf https://usa.visa.com/content/dam/VCOM/global/ms/documents/ve... https://usa.visa.com/content/dam/VCOM/regional/na/us/sites/documents/building-a-competitive-payments-platform-with-iso-20022.pdf https://usa.visa.com/content/dam/VCOM/regional/na/us/sites/d... Mastercard uses data sucking nag screens, but I don't think you actually need to read the papers to get the point: https://b2b.mastercard.com/news-and-insights/payments-modernization/getting-the-message-across/ https://b2b.mastercard.com/news-and-insights/payments-modern... https://b2b.mastercard.com/news-and-insights/report/iso-20022-message-standards/ https://b2b.mastercard.com/news-and-insights/report/iso-2002... In 2018 SWIFT decided to migrate. Do you seriously believe that VISA and Mastercard did not notice this when it happened? Do you think they've been watching India adopt ISO 20022 for years and not acted upon it? Edit: The reason adoption is fast when the devs finally can get to work is that it's XML, you get schema files and punch your programming button and generate a lot of the necessary code and then do the plumbing and call it a day.
- j16sdiz 2y agoI don't know the current state of affairs. Last time I worked on ISO20022 (almost 10 years ago), our system were doing a 1-to-1 mapping from ISO8583, keeping every bit of unmaintable shit one could imagine